Global privacy notice
Privacy Notice
This notice explains how Keski-Suomen Otto ja Pano Oy handles personal data about website visitors, business contacts, quote requesters, and customers worldwide.
1. Who is responsible
Keski-Suomen Otto ja Pano Oy, trading as Odoo Upgrade Done, is the controller for the personal data described in this notice.
Business ID: 2376890-1
Address: c/o Joona Heino, Herneaho 84, FI-41120 Puuppola, Finland
Email: support@odooupgradedone.com
We have not appointed a data protection officer because our present processing does not require one. Privacy requests may be sent to the email above.
2. Two different privacy roles
We act as controller for website use, enquiries, quote and project contacts, contracts, security, billing, and our own business records. This Privacy Notice covers that activity.
When a business customer gives us an Odoo database, filestore, addons, or related project files containing personal data, the customer ordinarily decides why that data exists and how it is used. For that Customer Personal Data, the customer is controller and we are processor. The Data Processing Agreement governs that work. Individuals whose data is inside a customer's Odoo system should normally contact that customer first.
3. Data we collect
| Category | Examples | Source |
|---|---|---|
| Business identity and contact data | Name, work email, company, role, country, billing contact, signature or acceptance record | You, your employer, or a colleague |
| Quote and project data | Current and target Odoo versions, module and file names, file sizes, admin username, notes, requirements, support messages, testing feedback, project status | You and project participants |
| Contract and transaction data | Quote, Order, price, currency, tax identifiers, invoice, payment status, Stripe transaction reference, delivery and download records | You, our records, and payment providers |
| Website and device data | IP address, date and time, requested URL, referrer, browser, device, server logs, security events | Your browser and our hosting/security providers |
| Optional analytics and advertising measurement data | Pages, approximate region, device and interaction data, Google Analytics identifiers, and a Google Ads click identifier recording that a visit came from one of our adverts | Your browser, only after you accept optional cookies |
| Communications and preferences | Emails, form submissions, checklist request, marketing choice, cookie choice, privacy requests | You |
| Compliance data | Records needed to prevent fraud, meet tax/accounting duties, screen sanctions, or establish legal claims | You, service providers, and public sources where appropriate |
We do not receive full payment-card numbers. Stripe or another payment provider collects payment credentials under its own privacy notice.
4. Why we use data and the legal basis
| Purpose | Legal basis where GDPR-style law applies |
|---|---|
| Respond to enquiries; prepare quotes; administer previews, Orders, testing, delivery, and support | Steps requested before a contract; performance of a contract; and legitimate interests in serving business customers |
| Verify authority and record acceptance of terms | Contract and legitimate interests in maintaining reliable agreement records |
| Invoice, collect payment, account for transactions, and meet tax duties | Contract and legal obligations |
| Operate, troubleshoot, secure, and prevent abuse of the website and upload service | Legitimate interests in a secure and reliable service and, where applicable, legal obligations |
| Measure website use with Google Analytics, and measure which of our adverts lead to quote requests with Google Ads | Consent; both remain off unless you opt in. Ad personalisation stays off either way |
| Send the checklist or other material you request | Steps at your request and legitimate interests in answering the request |
| Send occasional marketing email | Consent where required; otherwise legitimate interests only where local business-marketing law allows, always with an opt-out |
| Manage disputes, enforce terms, and comply with lawful requests | Legitimate interests, legal claims, and legal obligations |
| Plan and improve the service using aggregated or de-identified information | Legitimate interests; we do not use Customer Content to train general AI models |
Where we rely on legitimate interests, we consider the business context, necessity, and effect on individuals. You may object as described below. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful processing.
5. When data is required
A work email, migration versions, sufficient project information, and acceptance of the Service Terms are required to submit a quote request. Contract, billing, and tax data are required to place and pay an Order. If you do not provide required data, we may be unable to quote or deliver. Marketing and analytics consent are optional and have no effect on the service.
6. Who receives data
We disclose personal data only as reasonably needed to:
- hosting, object-storage, email, analytics, payment, accounting, and professional-adviser providers;
- personnel and contractors who need it for the quote or Order and are subject to confidentiality duties;
- tax, regulatory, law-enforcement, or judicial authorities when legally required or necessary to protect legal rights;
- a buyer, investor, lender, or adviser in a genuine corporate transaction, subject to suitable confidentiality; or
- another recipient at your direction or with your consent.
Our current Customer Personal Data service providers are listed on the Subprocessors page. Google receives analytics and advertising measurement data only after consent. Stripe and similar payment providers may act as independent controllers for payment, fraud-prevention, and legal-compliance purposes.
We do not sell personal data. We do not share personal data for cross-context behavioural advertising and do not use Customer Content for advertising.
7. International transfers
We are established in Finland and primarily process project data in the European Union. Some website, communications, analytics, or payment providers may process limited data in other countries. Those countries may have different privacy laws.
Where a restricted transfer mechanism is required, we use an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or another lawful safeguard, plus supplementary measures where appropriate. A copy of the relevant safeguard may be requested, subject to necessary redactions. Global customers may send business and project data to Finland subject to their local transfer requirements and the DPA.
8. Retention
| Data | Usual retention |
|---|---|
| Quote-only Customer Content | Deleted within 30 days after the quote expires or is declined, unless you ask us to proceed or law requires preservation |
| Paid project Customer Content and preview | Deleted within 30 days after confirmed delivery/download or within 60 days after delivery, whichever occurs first, unless the Order requires a different period |
| Upload and security logs | Usually 30 days, longer only for an active security investigation or legal need |
| Enquiries with no project | Up to 24 months after the last meaningful contact |
| Contract, acceptance, project, and business correspondence | For the agreement and usually six years afterward to establish and defend legal claims |
| Invoices and accounting material | Six or ten years, depending on the record, as required by Finnish accounting and tax law |
| Marketing contact and consent record | Until opt-out, then a minimal suppression record as needed to honour the opt-out |
| Analytics data | Up to 14 months in Google Analytics; your local analytics cookies expire as listed in the Cookie Policy |
| Privacy request records | Usually three years after resolution |
We may retain a record longer when reasonably necessary for litigation, a legal hold, fraud prevention, or a binding legal obligation. When deletion from an encrypted backup cannot occur immediately, the data is isolated from ordinary use and expires under the backup cycle.
9. Your choices and rights
Depending on where you live, you may have rights to access, obtain a copy, correct, delete, restrict, or object to processing; withdraw consent; request portability; and complain to a regulator. Some rights have legal exceptions. We will not discriminate against you for exercising a privacy right.
Send a request to support@odooupgradedone.com. Describe the right and the data involved. We may ask for information reasonably needed to verify identity and authority. If the request concerns personal data inside a customer's Odoo system, identify that customer; we will refer or assist under the DPA.
Use the unsubscribe link in marketing email or contact us to opt out. Use Cookie settings to change your analytics and advertising cookie consent.
10. EEA, United Kingdom, and Switzerland
Individuals in these regions have the GDPR-style rights described above. You may complain to the supervisory authority where you live or work. Our lead authority in Finland is the Office of the Data Protection Ombudsman. You are not required to contact us before complaining, although we welcome the chance to resolve the issue.
11. United States state privacy disclosures
For residents of US states with applicable comprehensive privacy laws, the categories collected, sources, purposes, and recipients are described in sections 3–6. In the preceding 12 months, we may have collected identifiers, internet/network activity, commercial information, professional information, communications, and inferences limited to project needs. We do not sell personal data, share it for cross-context behavioural advertising, or use it for targeted advertising. We do not use sensitive personal information to infer characteristics.
Where applicable, you may request access, correction, deletion, portability, or confirmation of processing, and may opt out of sale, targeted advertising, sharing, or qualifying profiling. Because we do none of the latter activities, no separate opt-out is needed. We use advertising cookies to measure our own advert performance only, with ad personalisation switched off, which is why no targeted-advertising opt-out applies. We honour recognised browser Global Privacy Control signals by keeping all optional cookies off for that browser unless you later choose otherwise.
California residents may use an authorised agent. We will verify the request and the agent's authority as permitted by law. If we deny a request and your state provides an appeal right, reply to the denial within 30 days with “Privacy appeal”.
12. Brazil and other regions
Where Brazil's LGPD applies, the controller is identified in section 1 and the purposes and legal bases are in section 4. You may request confirmation, access, correction, anonymisation, blocking, deletion, portability where regulated, information about sharing, review of consent, and other rights provided by the LGPD, and may contact Brazil's national data protection authority.
Residents of Canada, Australia, New Zealand, and other countries may exercise the access, correction, complaint, consent, and deletion rights available under their local law by contacting us. We apply the controls in this notice globally even where a local rule is less prescriptive.
13. Automated decisions and children's data
We do not make decisions producing legal or similarly significant effects about individuals solely by automated means. The service is for business customers and is not directed to children. Do not submit children's data unless it is necessary for an approved project, lawfully collected, and disclosed to us in advance under section 11 of the Service Terms.
14. Security
We use access restrictions, encryption in transit, protected object storage, confidentiality controls, data minimisation, and deletion procedures appropriate to the risk. Customer files are uploaded using time-limited direct storage links. No system can be guaranteed completely secure; please report a suspected issue to support@odooupgradedone.com.
15. Changes
We may update this notice as the service, providers, or law changes. The effective date above identifies the current version. We will provide additional notice when a change materially affects active customers or consent choices.